no-mistakes(document): Align vendor asset upgrade naming with committed files

This commit is contained in:
root
2026-09-09 01:44:56 +00:00
parent 05d768343c
commit 49b26926cf
+5 -2
View File
@@ -86,8 +86,11 @@ Frontend: Alpine.js + Tailwind CSS vendored same-origin (no CDN) — see
filenames → immutable cache `public, max-age=31536000, immutable`). Templates
must never reference a CDN; update `app/templates/base.html` when upgrading:
download `alpinejs@<ver>/dist/cdn.min.js` (jsDelivr) and the tailwind play
script (`cdn.tailwindcss.com/<ver>`), save as `app/static/vendor/<name>-<ver>.min.js`,
bump the `<script src>` + the regression file `tests/test_frontend_vendoring.py`.
script (`cdn.tailwindcss.com/<ver>`), save them under `app/static/vendor/`
mirroring the committed names (Alpine keeps `.min.js`, e.g.
`alpine-3.17.2.min.js`; the tailwind play file does not, e.g.
`tailwind-3.4.17.js`), then bump the `<script src>` + the
`VENDORED_SCRIPTS` tuple in the regression file `tests/test_frontend_vendoring.py`.
- HTML pages ship `Cache-Control: no-cache` and CSP is self-only
(`script-src`/`style-src 'self' 'unsafe-inline'`, `connect-src 'self'`); no
CDN host is allowed in CSP (`app/main.py::SecurityHeadersMiddleware`).